The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

138 decisions matching
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Apr 24, 2023Indexed Jun 30, 2026

CBSA’s use of commercial genetic genealogy in a deportation case contravenes the Privacy Act

Canadian Border Services Agency (CBSA)

A former refugee complained that the Canadian Border Services Agency (CBSA) contravened his privacy rights by using commercial genetic genealogy (FamilyTreeDNA) to determine his nationality for deportation. He alleged lack of legal authority, unnecessary collection, invalid consent, deceptive practices, inadequate disclosure limitation, and insufficient Personal Information Bank (PIB) description. The Office of the Privacy Commissioner (OPC) found that while the collection was directly related to CBSA's program, the agency contravened section 5 of the Privacy Act by failing to obtain valid, informed authorization for indirect collection from FTDNA. CBSA also contravened section 8 by making incidental disclosures of the complainant's personal information to other FTDNA users, failing to monitor account settings, and not using a pseudonym. Furthermore, the CBSA's PIB descriptions were non-compliant with section 11, as they did not adequately describe the collection of genetic profiles of other FTDNA users. The OPC made several recommendations, which CBSA committed to implement for most parts, but two accounts remained open at the time of the report, leading to an ongoing, unresolved contravention. Consequently, the complaint was found well-founded in part and conditionally resolved in part.

Quick view

Privacy ActWell-founded

CBSA’s use of commercial genetic genealogy in a deportation case contravenes the Privacy Act

Apr 24, 2023
Adjudicator: Philippe Dufresne
Plain-Language Summary

A former refugee complained that the Canadian Border Services Agency (CBSA) contravened his privacy rights by using commercial genetic genealogy (FamilyTreeDNA) to determine his nationality for deportation. He alleged lack of legal authority, unnecessary collection, invalid consent, deceptive practices, inadequate disclosure limitation, and insufficient Personal Information Bank (PIB) description. The Office of the Privacy Commissioner (OPC) found that while the collection was directly related to CBSA's program, the agency contravened section 5 of the Privacy Act by failing to obtain valid, informed authorization for indirect collection from FTDNA. CBSA also contravened section 8 by making incidental disclosures of the complainant's personal information to other FTDNA users, failing to monitor account settings, and not using a pseudonym. Furthermore, the CBSA's PIB descriptions were non-compliant with section 11, as they did not adequately describe the collection of genetic profiles of other FTDNA users. The OPC made several recommendations, which CBSA committed to implement for most parts, but two accounts remained open at the time of the report, leading to an ongoing, unresolved contravention. Consequently, the complaint was found well-founded in part and conditionally resolved in part.

Key Issues
  • Whether CBSA's collection of genetic genealogy information was directly related to an operating program or activity under s.4 of the Privacy Act
  • Whether CBSA collected unnecessary information under s.4 of the Privacy Act
  • Whether CBSA obtained valid authorization from the complainant for the indirect collection of his personal information from FTDNA under s.5(1) of the Privacy Act
  • Whether the complainant's consent for indirect collection was voluntary and not given under duress
  • Whether the complainant was adequately informed about FTDNA's terms and his rights as a DNA donor for valid authorization
  • Whether CBSA acted deceptively in its collection via FTDNA
  • Whether the incidental indirect collection of genetic profile information of hundreds of other individuals contravened s.5(1) of the Privacy Act
  • Whether CBSA's incidental disclosures of the complainant's personal information contravened s.8 of the Privacy Act
  • Whether allowing potential disclosure of the complainant's personal information to other law enforcement bodies (via "law enforcement matching" opt-in) contravened s.8 of the Privacy Act
  • Whether the disclosure of ancillary personal information (ethnicity) to genetic matches contravened s.8 of the Privacy Act
  • Whether the disclosure of the complainant's identity to genetic matches (failure to use a pseudonym) contravened s.8 of the Privacy Act
  • Whether CBSA's Personal Information Bank (PIB) descriptions complied with the transparency obligations under s.11 of the Privacy Act
  • Whether the PIB adequately described the collection of biometric information for individuals subject to removal orders
  • Whether the PIB adequately described the collection of genetic profiles of other FTDNA users (relatives of individuals subject to removal orders)
Federal (Canada)Privacy ActWell-founded & resolved
Federal (Canada) flag
Apr 13, 2023Indexed Jun 30, 2026

Investigation of Correctional Service Canada’s collection and disclosure of an individual’s personal information from Facebook related to an employee’s 699-leave

Correctional Service Canada

A complaint was filed against Correctional Service Canada (CSC) by the spouse of an employee, alleging inappropriate collection and disclosure of personal information from their public Facebook page. The information was collected by an assistant warden to investigate the employee's use of 'other leave with pay (699)' during the COVID-19 pandemic. The OPC found that significant portions of the collected information were not directly related to an operating program or activity of CSC, thus contravening Section 4 of the Privacy Act. The OPC also noted that the exclusion for publicly available information under subsection 69(2) of the Privacy Act applies only to use and disclosure, not collection. CSC subsequently deleted the collected screenshots and committed to developing guidance for managers on collecting information in a labour relations context. The complainant also raised concerns about CSC's internal complaint process, which CSC acknowledged was mishandled.

Quick view

Privacy ActWell-founded & resolved

Investigation of Correctional Service Canada’s collection and disclosure of an individual’s personal information from Facebook related to an employee’s 699-leave

Apr 13, 2023
Adjudicator: Philippe Dufresne
Plain-Language Summary

A complaint was filed against Correctional Service Canada (CSC) by the spouse of an employee, alleging inappropriate collection and disclosure of personal information from their public Facebook page. The information was collected by an assistant warden to investigate the employee's use of 'other leave with pay (699)' during the COVID-19 pandemic. The OPC found that significant portions of the collected information were not directly related to an operating program or activity of CSC, thus contravening Section 4 of the Privacy Act. The OPC also noted that the exclusion for publicly available information under subsection 69(2) of the Privacy Act applies only to use and disclosure, not collection. CSC subsequently deleted the collected screenshots and committed to developing guidance for managers on collecting information in a labour relations context. The complainant also raised concerns about CSC's internal complaint process, which CSC acknowledged was mishandled.

Key Issues
  • Whether the collection of personal information from a public Facebook page was directly related to an operating program or activity of CSC under Section 4 of the Privacy Act
  • Whether the exclusion for publicly available information under subsection 69(2) of the Privacy Act applies to the collection of personal information
  • Whether the subsequent disclosure of the collected information was appropriate
  • Whether CSC's internal process for handling privacy complaints from the public was adequate
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Mar 31, 2023Indexed Jun 30, 2026

Immigration and Refugee Board of Canada wrongly disclosed intimate and medical information to an employee’s management team via a fitness to work report

Immigration and Refugee Board of Canada (IRB)

An employee of the Immigration and Refugee Board of Canada (IRB) complained that their intimate personal and sensitive medical information, contained in a Fitness to Work (FTW) report, was disclosed to their management team without consent and for no reasonable purpose. The OPC investigated whether the IRB respected section 8 of the Privacy Act, specifically regarding consent and consistent use. The IRB argued the disclosure was a consistent use, but the OPC found that while some information disclosure was consistent, the highly intimate personal and sensitive medical information was not. The OPC concluded that the IRB contravened the Act by disclosing information internally that fell outside what is permissible. Despite some new processes, the IRB did not fully acknowledge wrongdoing or agree to all recommendations, leading to a well-founded and unresolved finding.

Quick view

Privacy ActWell-founded

Immigration and Refugee Board of Canada wrongly disclosed intimate and medical information to an employee’s management team via a fitness to work report

Mar 31, 2023
Adjudicator: Philippe Dufresne
Plain-Language Summary

An employee of the Immigration and Refugee Board of Canada (IRB) complained that their intimate personal and sensitive medical information, contained in a Fitness to Work (FTW) report, was disclosed to their management team without consent and for no reasonable purpose. The OPC investigated whether the IRB respected section 8 of the Privacy Act, specifically regarding consent and consistent use. The IRB argued the disclosure was a consistent use, but the OPC found that while some information disclosure was consistent, the highly intimate personal and sensitive medical information was not. The OPC concluded that the IRB contravened the Act by disclosing information internally that fell outside what is permissible. Despite some new processes, the IRB did not fully acknowledge wrongdoing or agree to all recommendations, leading to a well-founded and unresolved finding.

Key Issues
  • Whether the IRB obtained valid consent for the disclosure of the FTW report to the management team under section 8(1) of the Privacy Act
  • Whether the disclosure of intimate personal and sensitive medical information in the FTW report to the management team was a 'consistent use' under section 8(2)(a) of the Privacy Act
  • Whether the IRB adhered to the Treasury Board Secretariat's Occupational Health Evaluation Standard regarding disclosure of medical information to employers
Federal (Canada)Privacy ActWell-founded & resolved
Federal (Canada) flag
Feb 23, 2023Indexed Jun 30, 2026

Failure to publish a personal information bank description on Zero-Emissions Program contravenes the Privacy Act

Transport Canada

An individual complained that Transport Canada collected his personal information for the "Incentives for Zero-Emission Vehicles Program" (iZEV) without a publicly available Personal Information Bank (PIB) description, as required by the Privacy Act. Transport Canada launched the iZEV program in May 2019 but did not submit a PIB description to the Treasury Board Secretariat (TBS) for approval until 19 months later. The OPC found that both Transport Canada and TBS contributed to the contravention, as TBS failed to approve and publish the PIB description in a timely manner. Although Transport Canada eventually published the PIB, TBS declined to implement the OPC's recommendations for service standards, citing complexity, but outlined internal process improvements. The OPC acknowledged TBS's efforts to address the backlog.

Quick view

Privacy ActWell-founded & resolved

Failure to publish a personal information bank description on Zero-Emissions Program contravenes the Privacy Act

Feb 23, 2023
Adjudicator: Philippe Dufresne
Plain-Language Summary

An individual complained that Transport Canada collected his personal information for the "Incentives for Zero-Emission Vehicles Program" (iZEV) without a publicly available Personal Information Bank (PIB) description, as required by the Privacy Act. Transport Canada launched the iZEV program in May 2019 but did not submit a PIB description to the Treasury Board Secretariat (TBS) for approval until 19 months later. The OPC found that both Transport Canada and TBS contributed to the contravention, as TBS failed to approve and publish the PIB description in a timely manner. Although Transport Canada eventually published the PIB, TBS declined to implement the OPC's recommendations for service standards, citing complexity, but outlined internal process improvements. The OPC acknowledged TBS's efforts to address the backlog.

Key Issues
  • Whether Transport Canada failed to ensure personal information collected for the iZEV program was included in a publicly available PIB description as required by section 10 of the Privacy Act
  • Whether Transport Canada obtained TBS approval for a new PIB before implementing the iZEV program as required by subsection 71(4) of the Privacy Act and the TBS Directive on Privacy Impact Assessment
  • Whether TBS fulfilled its responsibility under section 11 of the Privacy Act to ensure timely publication of PIB descriptions
  • Whether the lack of a timely PIB approval process by TBS impacts the operability of the PIB regime under the Privacy Act
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
Feb 15, 2023Indexed Jun 30, 2026

TBS email breach illustrates the importance of considering context when assessing impact of a breach

Treasury Board of Canada Secretariat (TBS)

Twenty complainants, current or former federal government employees, alleged that the Treasury Board of Canada Secretariat (TBS) improperly disclosed their personal information. TBS mistakenly sent two emails to 400 applicants for the Severe Phoenix Impacts program using the 'cc' field instead of 'bcc', revealing email addresses (some with names) and the fact they had filed a claim for Phoenix-related damages. The OPC found that the disclosure was not authorized under the Privacy Act, making the complaints well-founded. While TBS acknowledged the error, it initially deemed the breach non-material, a conclusion the OPC disagreed with, emphasizing the importance of contextual factors in assessing harm. TBS agreed to implement two of the OPC's three recommendations, but not the one concerning incorporating the findings on materiality into its policy instruments. The OPC concluded the complaints were well-founded and conditionally resolved in part, expressing ongoing concern about TBS's assessment of breach materiality.

Quick view

Privacy ActWell-founded & conditionally resolved

TBS email breach illustrates the importance of considering context when assessing impact of a breach

Feb 15, 2023
Adjudicator: Philippe Dufresne
Plain-Language Summary

Twenty complainants, current or former federal government employees, alleged that the Treasury Board of Canada Secretariat (TBS) improperly disclosed their personal information. TBS mistakenly sent two emails to 400 applicants for the Severe Phoenix Impacts program using the 'cc' field instead of 'bcc', revealing email addresses (some with names) and the fact they had filed a claim for Phoenix-related damages. The OPC found that the disclosure was not authorized under the Privacy Act, making the complaints well-founded. While TBS acknowledged the error, it initially deemed the breach non-material, a conclusion the OPC disagreed with, emphasizing the importance of contextual factors in assessing harm. TBS agreed to implement two of the OPC's three recommendations, but not the one concerning incorporating the findings on materiality into its policy instruments. The OPC concluded the complaints were well-founded and conditionally resolved in part, expressing ongoing concern about TBS's assessment of breach materiality.

Key Issues
  • Whether the disclosure of personal information via email was authorized under the Privacy Act
  • Whether the privacy breach was 'material' in nature according to TBS's guidelines
  • Whether TBS's assessment of the breach's materiality was appropriate
  • Whether the context of the personal information disclosed should be considered when assessing the risk of injury or harm
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
Dec 14, 2022Indexed Jun 30, 2026

IRCC email breach creates risk of harm to individuals seeking Afghan emergency assistance

Immigration, Refugees and Citizenship Canada

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint against Immigration, Refugees and Citizenship Canada (IRCC) regarding a privacy breach involving 636 individuals seeking emergency assistance related to the situation in Afghanistan. IRCC inadvertently disclosed recipients' email addresses, and in some cases thumbnail photos, by using the "TO" field instead of "BCC" in four mass emails. This disclosure revealed that individuals had inquired about sensitive emergency measures, posing potential life-threatening risks. The OPC found that IRCC contravened section 8 of the Privacy Act by disclosing personal information without a permissible purpose. While IRCC took immediate steps to mitigate the impact on affected individuals, the OPC determined that its preventative measures were initially insufficient. IRCC subsequently revised its internal procedures, implemented a "two pairs of eyes" rule, limited recipients, introduced a secure webform, and committed to exploring further technological solutions. The OPC was satisfied with IRCC's actions and considered the matter closed.

Quick view

Privacy ActWell-founded & conditionally resolved

IRCC email breach creates risk of harm to individuals seeking Afghan emergency assistance

Dec 14, 2022
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint against Immigration, Refugees and Citizenship Canada (IRCC) regarding a privacy breach involving 636 individuals seeking emergency assistance related to the situation in Afghanistan. IRCC inadvertently disclosed recipients' email addresses, and in some cases thumbnail photos, by using the "TO" field instead of "BCC" in four mass emails. This disclosure revealed that individuals had inquired about sensitive emergency measures, posing potential life-threatening risks. The OPC found that IRCC contravened section 8 of the Privacy Act by disclosing personal information without a permissible purpose. While IRCC took immediate steps to mitigate the impact on affected individuals, the OPC determined that its preventative measures were initially insufficient. IRCC subsequently revised its internal procedures, implemented a "two pairs of eyes" rule, limited recipients, introduced a secure webform, and committed to exploring further technological solutions. The OPC was satisfied with IRCC's actions and considered the matter closed.

Key Issues
  • Whether IRCC's disclosure of personal information via mass email contravened section 8 of the Privacy Act
  • Whether IRCC had sufficient administrative and procedural controls in place to prevent accidental disclosures of sensitive personal information when communicating by mass email
  • Whether IRCC's measures to mitigate the impact of the incident on affected individuals were adequate
  • Whether IRCC's actions to reduce the risk of recurrence of similar incidents in the future were adequate
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Dec 2, 2022Indexed Jun 30, 2026

Canada Border Services Agency over-discloses personal information to the Information Commissioner in relation to an ATIA request

Canada Border Services Agency (CBSA)

An individual complained that the Canada Border Services Agency (CBSA) over-disclosed their personal information to the Information Commissioner (IC) when seeking approval to decline two Access to Information Act (ATIA) requests. The CBSA provided not only information related to the ATIA requests but also a sensitive labour relations report about the complainant. The CBSA argued the disclosure was a "consistent use" under paragraph 8(2)(a) of the Privacy Act, as the information was collected in the context of workplace conflict and the disclosure was to determine how to handle the complainant's requests for their personal information. The OPC found that while information related to the ATIA requests was a consistent use, the disclosure of the labour relations report was not, as its original purpose (addressing workplace conflict) was distinct from responding to ATIA requests. The OPC concluded that the CBSA contravened section 8 of the Privacy Act and recommended the CBSA develop guidance for consistent use disclosures. The CBSA disagreed with the finding and declined to implement the recommendation, leading to a "well-founded and not resolved" outcome.

Quick view

Privacy ActWell-founded

Canada Border Services Agency over-discloses personal information to the Information Commissioner in relation to an ATIA request

Dec 2, 2022
Adjudicator: Philippe Dufresne
Plain-Language Summary

An individual complained that the Canada Border Services Agency (CBSA) over-disclosed their personal information to the Information Commissioner (IC) when seeking approval to decline two Access to Information Act (ATIA) requests. The CBSA provided not only information related to the ATIA requests but also a sensitive labour relations report about the complainant. The CBSA argued the disclosure was a "consistent use" under paragraph 8(2)(a) of the Privacy Act, as the information was collected in the context of workplace conflict and the disclosure was to determine how to handle the complainant's requests for their personal information. The OPC found that while information related to the ATIA requests was a consistent use, the disclosure of the labour relations report was not, as its original purpose (addressing workplace conflict) was distinct from responding to ATIA requests. The OPC concluded that the CBSA contravened section 8 of the Privacy Act and recommended the CBSA develop guidance for consistent use disclosures. The CBSA disagreed with the finding and declined to implement the recommendation, leading to a "well-founded and not resolved" outcome.

Key Issues
  • Whether the disclosure of personal information to the Information Commissioner was for a "consistent use" under paragraph 8(2)(a) of the Privacy Act
  • Whether information collected for administering ATIA requests can be disclosed to the IC as a consistent use
  • Whether a labour relations report, originally collected for addressing workplace conflict, can be disclosed to the IC as a consistent use in the context of ATIA requests
Federal (Canada)Privacy ActWell-founded & resolved
Federal (Canada) flag
May 20, 2022Indexed Jun 30, 2026

Investigation into a privacy breach at a Canada Border Services Agency contractor

Canada Border Services Agency

The Office of the Privacy Commissioner of Canada (OPC) investigated a ransomware attack on a Canada Border Services Agency (CBSA) contractor that resulted in the compromise of licence plate image files. Malicious actors accessed and copied approximately 1.4 million CBSA licence plate images, with about 11,000 confirmed to have been posted on the Dark Web. The CBSA initially contended that licence plate information was not personal information and that its contract with the third-party contractor was adequate. However, the OPC determined that licence plate image files, when combined with metadata revealing border crossing time and location, constitute personal information under the Privacy Act. The investigation found that the CBSA's contract with the contractor lacked sufficient clauses for security safeguards and appropriate data retention. Consequently, the OPC found the complaint to be well-founded, concluding that the CBSA contravened the disclosure provisions of the Act. The CBSA accepted the OPC's recommendations to update its contracts with clear privacy clauses, ensure proper safeguards and retention limits, and verify compliance, leading to the complaint being resolved.

Quick view

Privacy ActWell-founded & resolved

Investigation into a privacy breach at a Canada Border Services Agency contractor

May 20, 2022
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated a ransomware attack on a Canada Border Services Agency (CBSA) contractor that resulted in the compromise of licence plate image files. Malicious actors accessed and copied approximately 1.4 million CBSA licence plate images, with about 11,000 confirmed to have been posted on the Dark Web. The CBSA initially contended that licence plate information was not personal information and that its contract with the third-party contractor was adequate. However, the OPC determined that licence plate image files, when combined with metadata revealing border crossing time and location, constitute personal information under the Privacy Act. The investigation found that the CBSA's contract with the contractor lacked sufficient clauses for security safeguards and appropriate data retention. Consequently, the OPC found the complaint to be well-founded, concluding that the CBSA contravened the disclosure provisions of the Act. The CBSA accepted the OPC's recommendations to update its contracts with clear privacy clauses, ensure proper safeguards and retention limits, and verify compliance, leading to the complaint being resolved.

Key Issues
  • Whether licence plate image files, including associated metadata (jurisdiction, characters, date, time, border crossing site, lane number), constitute personal information under Section 3 of the Privacy Act.
  • Whether the unauthorized access and disclosure of these licence plate image files constituted an improper disclosure under Section 8 of the Privacy Act.
  • Whether the Canada Border Services Agency (CBSA) had adequate security safeguards in place, particularly in its contractual arrangements with a third-party contractor, to protect personal information.
  • Whether the data retention practices for licence plate image files by the CBSA and its contractor were appropriate and compliant with the Privacy Act.
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
May 13, 2022Indexed Jun 30, 2026

DND breached the Privacy Act in disclosing the identity of a workplace violence complainant who had an expectation of confidentiality

Department of National Defence (DND)

An individual complained that the Department of National Defence (DND) breached the Privacy Act by disclosing their identity as a workplace violence (WPV) complainant to an investigator conducting a separate administrative investigation into the complainant's conduct. DND argued the disclosure was a "consistent use" under paragraph 8(2)(a) of the Privacy Act, necessary to address allegations against the individual. The OPC found that while disclosure to labour relations was a consistent use, disclosure to the investigator was not, as the consent form created a reasonable expectation of confidentiality for the WPV complaint. The OPC concluded that the disclosure to the investigator was not directly connected to the original purpose of collecting the WPV complaint information. DND committed to implementing recommendations to ensure future disclosures align with participants' reasonable expectations.

Quick view

Privacy ActWell-founded & conditionally resolved

DND breached the Privacy Act in disclosing the identity of a workplace violence complainant who had an expectation of confidentiality

May 13, 2022
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that the Department of National Defence (DND) breached the Privacy Act by disclosing their identity as a workplace violence (WPV) complainant to an investigator conducting a separate administrative investigation into the complainant's conduct. DND argued the disclosure was a "consistent use" under paragraph 8(2)(a) of the Privacy Act, necessary to address allegations against the individual. The OPC found that while disclosure to labour relations was a consistent use, disclosure to the investigator was not, as the consent form created a reasonable expectation of confidentiality for the WPV complaint. The OPC concluded that the disclosure to the investigator was not directly connected to the original purpose of collecting the WPV complaint information. DND committed to implementing recommendations to ensure future disclosures align with participants' reasonable expectations.

Key Issues
  • Whether the disclosure of the WPV complainant's identity to labour relations was a "consistent use" under paragraph 8(2)(a) of the Privacy Act
  • Whether the disclosure of the WPV complainant's identity to an investigator for a separate administrative investigation was a "consistent use" under paragraph 8(2)(a) of the Privacy Act
  • Whether the consent form provided by DND created a reasonable expectation of confidentiality regarding the complainant's identity
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
Jun 10, 2021Indexed Jun 30, 2026

Police use of Facial Recognition Technology in Canada and the way forward

Royal Canadian Mounted Police (RCMP)

The Office of the Privacy Commissioner of Canada (OPC) investigated the Royal Canadian Mounted Police (RCMP)'s use of facial recognition technology from Clearview AI. The OPC found that the RCMP contravened Section 4 of the Privacy Act by collecting personal information from Clearview AI, as Clearview AI itself had collected this information unlawfully under PIPEDA and provincial privacy laws. The investigation revealed serious and systemic gaps in the RCMP's policies and systems for tracking, identifying, assessing, and controlling novel collections of personal information. Although the RCMP disagreed with the finding of contravention, it committed to implementing the OPC's recommendations for systemic changes, improved training, and robust controls. The OPC concluded that the matter was well-founded and conditionally resolved, pending the full implementation of these recommendations.

Quick view

Privacy ActWell-founded & conditionally resolved

Police use of Facial Recognition Technology in Canada and the way forward

Jun 10, 2021
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated the Royal Canadian Mounted Police (RCMP)'s use of facial recognition technology from Clearview AI. The OPC found that the RCMP contravened Section 4 of the Privacy Act by collecting personal information from Clearview AI, as Clearview AI itself had collected this information unlawfully under PIPEDA and provincial privacy laws. The investigation revealed serious and systemic gaps in the RCMP's policies and systems for tracking, identifying, assessing, and controlling novel collections of personal information. Although the RCMP disagreed with the finding of contravention, it committed to implementing the OPC's recommendations for systemic changes, improved training, and robust controls. The OPC concluded that the matter was well-founded and conditionally resolved, pending the full implementation of these recommendations.

Key Issues
  • Whether the RCMP's collection of personal information from Clearview AI was directly related to an operating program or activity under Section 4 of the Privacy Act.
  • Whether a government institution can collect personal information from a third party that collected the information unlawfully.
  • Whether the RCMP had adequate controls to prevent future similar contraventions when collecting novel personal information.
  • Whether the RCMP had sufficient knowledge of its obligations under the Privacy Act and common law regarding personal information collection.
  • Whether the RCMP had adequate awareness and tracking systems for novel personal information collections.
  • Whether the RCMP had processes to identify potential compliance issues before undertaking novel collections.
  • Whether the RCMP had processes to complete timely assessments (like PIAs) when warranted.
  • Whether the RCMP had effective controls on collection, including policies and monitoring for unauthorized collections.
  • Whether the RCMP's use of Clearview AI constituted a justifiable exercise of police powers under common law (Waterfield test).
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
May 3, 2021Office of the Privacy Commissioner Compliance Monitoring of Statistics Canada’s Financial Transactions Project and Credit Agency Data ProjectIndexed Jun 30, 2026

Office of the Privacy Commissioner Compliance Monitoring of Statistics Canada’s Financial Transactions Project and Credit Agency Data Project: Final Report

Statistics Canada

This report is a compliance monitoring review by the Office of the Privacy Commissioner (OPC) of Statistics Canada's (StatCan) redesigned Financial Transactions Project and Credit Agency Data Project. It follows an earlier OPC investigation that found no contraventions of the Privacy Act but identified significant privacy concerns, leading to recommendations for StatCan to incorporate necessity and proportionality principles. The OPC assessed StatCan's progress, noting reductions in data collection and the implementation of privacy-enhancing measures like a data ethics secretariat and an external ethics body. However, the OPC found that the redesigned project plans still lacked sufficient specificity in describing public goals, failed to demonstrate effectiveness, and did not adequately analyze privacy impacts in context. The OPC concluded that while progress was made, "more work needs to be done" to fully meet its assessment criteria for necessity and proportionality. Consequently, the OPC issued four new recommendations, including describing public goals with greater precision, revisiting effectiveness, analyzing privacy in context, and resubmitting the plans for further review before final implementation. The outcome is classified as well-founded-conditionally-resolved, reflecting partial implementation and the need for further action.

Quick view

Privacy ActWell-founded & conditionally resolved

Office of the Privacy Commissioner Compliance Monitoring of Statistics Canada’s Financial Transactions Project and Credit Agency Data Project: Final Report

May 3, 2021Office of the Privacy Commissioner Compliance Monitoring of Statistics Canada’s Financial Transactions Project and Credit Agency Data Project
Adjudicator: Daniel Therrien
Plain-Language Summary

This report is a compliance monitoring review by the Office of the Privacy Commissioner (OPC) of Statistics Canada's (StatCan) redesigned Financial Transactions Project and Credit Agency Data Project. It follows an earlier OPC investigation that found no contraventions of the Privacy Act but identified significant privacy concerns, leading to recommendations for StatCan to incorporate necessity and proportionality principles. The OPC assessed StatCan's progress, noting reductions in data collection and the implementation of privacy-enhancing measures like a data ethics secretariat and an external ethics body. However, the OPC found that the redesigned project plans still lacked sufficient specificity in describing public goals, failed to demonstrate effectiveness, and did not adequately analyze privacy impacts in context. The OPC concluded that while progress was made, "more work needs to be done" to fully meet its assessment criteria for necessity and proportionality. Consequently, the OPC issued four new recommendations, including describing public goals with greater precision, revisiting effectiveness, analyzing privacy in context, and resubmitting the plans for further review before final implementation. The outcome is classified as well-founded-conditionally-resolved, reflecting partial implementation and the need for further action.

Key Issues
  • Whether the redesigned Financial Transactions Project and Credit Agency Data Project met the principles of necessity and proportionality.
  • Whether the public goals of the projects were described with a level of specificity and precision commensurate with privacy impacts.
  • Whether the effectiveness of the projects was demonstrated.
  • Whether privacy impacts were given sufficient analysis in context, considering risk of harm to individuals and broad-based harms.
  • Whether StatCan's Necessity and Proportionality Framework aligned with OPC's assessment criteria.
  • Whether less privacy-intrusive alternatives were adequately considered and compared.
Federal (Canada)Privacy ActWell-founded & resolved
Federal (Canada) flag
Nov 17, 2020Indexed Jun 30, 2026

Employer’s disclosure related to a transgender individual was contrary to the Privacy Act

A federal government institution

An employee complained that a federal government institution breached her privacy by disclosing her transgender identity and the reasons for her transfer to her new manager and colleagues without her consent. The complainant had explicitly requested confidentiality due to prior workplace harassment related to her gender identity, and the employer had assured her of discretion. The institution's internal review confirmed that managers disclosed this sensitive information, believing it necessary to support the employee and her new supervisor, but acknowledged this was an error and contrary to internal policies. The OPC found that the disclosure was made without consent, contravening section 8(1) of the Privacy Act. The institution recognized the breach and committed to improving policies and providing transgender awareness education. The OPC recommended updating policies to prevent similar incidents, and the institution created new guidance for its staff.

Quick view

Privacy ActWell-founded & resolved

Employer’s disclosure related to a transgender individual was contrary to the Privacy Act

Nov 17, 2020
Adjudicator: Daniel Therrien
Plain-Language Summary

An employee complained that a federal government institution breached her privacy by disclosing her transgender identity and the reasons for her transfer to her new manager and colleagues without her consent. The complainant had explicitly requested confidentiality due to prior workplace harassment related to her gender identity, and the employer had assured her of discretion. The institution's internal review confirmed that managers disclosed this sensitive information, believing it necessary to support the employee and her new supervisor, but acknowledged this was an error and contrary to internal policies. The OPC found that the disclosure was made without consent, contravening section 8(1) of the Privacy Act. The institution recognized the breach and committed to improving policies and providing transgender awareness education. The OPC recommended updating policies to prevent similar incidents, and the institution created new guidance for its staff.

Key Issues
  • Whether information about an individual's transgender identity is personal information requiring protection under the Privacy Act
  • Whether the institution disclosed the complainant's personal information without consent
  • Whether the disclosure was contrary to section 8(1) of the Privacy Act
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
Aug 7, 2020Indexed Jun 30, 2026

RCMP contravened the Act by using certain types of non-conviction information for vulnerable sector checks without consent

Royal Canadian Mounted Police (RCMP)

Three individuals complained about the Royal Canadian Mounted Police's (RCMP) use of non-conviction information in vulnerable sector (VS) checks, which they required for employment or volunteer positions. The complainants alleged that the RCMP inappropriately used non-criminal information, including mental health incidents, without proper consent. The OPC found that for two of the complaints, the RCMP contravened section 7 of the Privacy Act because the consent forms did not clearly inform applicants about the types of non-conviction information that would be used. While the RCMP argued consent was obtained, the OPC determined it was not informed consent in these cases. The OPC also concluded that the RCMP's broad policy of reporting non-conviction information, including mental health incidents, was not proportional or minimally intrusive compared to more restrictive provincial models. However, the complaint regarding the RCMP's retention period for personal information was found not well-founded, as it complied with the minimum requirements of the Privacy Regulations. The RCMP agreed to revise its consent forms and policy to address the OPC's concerns, leading to a well-founded and conditionally resolved outcome for the two complaints.

Quick view

Privacy ActWell-founded & conditionally resolved

RCMP contravened the Act by using certain types of non-conviction information for vulnerable sector checks without consent

Aug 7, 2020
Adjudicator: Daniel Therrien
Plain-Language Summary

Three individuals complained about the Royal Canadian Mounted Police's (RCMP) use of non-conviction information in vulnerable sector (VS) checks, which they required for employment or volunteer positions. The complainants alleged that the RCMP inappropriately used non-criminal information, including mental health incidents, without proper consent. The OPC found that for two of the complaints, the RCMP contravened section 7 of the Privacy Act because the consent forms did not clearly inform applicants about the types of non-conviction information that would be used. While the RCMP argued consent was obtained, the OPC determined it was not informed consent in these cases. The OPC also concluded that the RCMP's broad policy of reporting non-conviction information, including mental health incidents, was not proportional or minimally intrusive compared to more restrictive provincial models. However, the complaint regarding the RCMP's retention period for personal information was found not well-founded, as it complied with the minimum requirements of the Privacy Regulations. The RCMP agreed to revise its consent forms and policy to address the OPC's concerns, leading to a well-founded and conditionally resolved outcome for the two complaints.

Key Issues
  • Whether the use of non-conviction information by the RCMP for VS checks was done with informed consent consistent with section 7 of the Privacy Act.
  • Whether the RCMP's policy of reporting non-conviction information broadly, including mental health incidents, in VS checks was proportional or minimally intrusive.
  • Whether the RCMP should amend its policies with respect to the use of non-conviction information in VS checks.
  • Whether the RCMP contravened the Act by retaining Complainant 2’s personal information for too long.
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
Aug 7, 2020Indexed Jun 30, 2026

PA-048557, PA-048561 — Canadian Air Transport Security Authority (CATSA)

Canadian Air Transport Security Authority (CATSA)

An individual complained that the Canadian Air Transport Security Authority (CATSA) contravened the Privacy Act by collecting and disclosing his personal information to police after finding legal medical cannabis during a security screening. The complainant argued that CATSA's mandate is aviation security, not general law enforcement, and that cannabis is not a prohibited item. CATSA maintained that its actions were incidental to its mandate and in the public interest, consistent with its regulator's direction. The OPC found that CATSA lacked the legal authority under section 4 of the Privacy Act to collect personal information for general law enforcement purposes related to cannabis, as cannabis is not on the Prohibited Items List and does not pose an aviation security threat. Similarly, the OPC concluded that the disclosure of this personal information to police was not consistent with section 8 of the Privacy Act. However, the OPC found CATSA's practice of destroying records related to such searches to be consistent with section 6 of the Act. The OPC recommended that CATSA cease unauthorized collection and disclosure of personal information related to cannabis and destroy any existing records, which CATSA agreed to implement.

Quick view

Privacy ActWell-founded & conditionally resolved

PA-048557, PA-048561 — Canadian Air Transport Security Authority (CATSA)

Aug 7, 2020
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that the Canadian Air Transport Security Authority (CATSA) contravened the Privacy Act by collecting and disclosing his personal information to police after finding legal medical cannabis during a security screening. The complainant argued that CATSA's mandate is aviation security, not general law enforcement, and that cannabis is not a prohibited item. CATSA maintained that its actions were incidental to its mandate and in the public interest, consistent with its regulator's direction. The OPC found that CATSA lacked the legal authority under section 4 of the Privacy Act to collect personal information for general law enforcement purposes related to cannabis, as cannabis is not on the Prohibited Items List and does not pose an aviation security threat. Similarly, the OPC concluded that the disclosure of this personal information to police was not consistent with section 8 of the Privacy Act. However, the OPC found CATSA's practice of destroying records related to such searches to be consistent with section 6 of the Act. The OPC recommended that CATSA cease unauthorized collection and disclosure of personal information related to cannabis and destroy any existing records, which CATSA agreed to implement.

Key Issues
  • Whether the collection of personal information from travellers found to be in possession of cannabis is consistent with section 4 of the Privacy Act
  • Whether the disclosure of the personal information of travellers found to be in possession of cannabis is consistent with section 8 of the Privacy Act
  • Whether CATSA’s record retention practices in terms of the personal information collected from travellers found to be in possession of cannabis are consistent with section 6 of the Privacy Act
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
Aug 7, 2020Indexed Jun 30, 2026

Review of passport protection practices of four federal institutions

Immigration, Refugees and Citizenship Canada (IRCC)

The Office of the Privacy Commissioner of Canada (OPC) conducted a review under section 37 of the Privacy Act into the passport protection practices of Immigration, Refugees and Citizenship Canada (IRCC), Employment and Social Development Canada (ESDC), Global Affairs Canada (GAC), and Canada Post Corporation (CPC). While the OPC found generally reasonable measures to prevent unauthorized disclosures of passports, it identified areas for improvement in incident detection, remediation for affected individuals, and lesson-learning from breaches. Specifically, the OPC noted inconsistent assessments of breach materiality, delays in notifying affected individuals, and a lack of concrete assistance such as credit monitoring. The OPC issued recommendations for consistent guidance on materiality, timely notification standards, offering mitigation measures, and robust incident assessment processes. All four institutions agreed to implement these recommendations.

Quick view

Privacy ActWell-founded & conditionally resolved

Review of passport protection practices of four federal institutions

Aug 7, 2020
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) conducted a review under section 37 of the Privacy Act into the passport protection practices of Immigration, Refugees and Citizenship Canada (IRCC), Employment and Social Development Canada (ESDC), Global Affairs Canada (GAC), and Canada Post Corporation (CPC). While the OPC found generally reasonable measures to prevent unauthorized disclosures of passports, it identified areas for improvement in incident detection, remediation for affected individuals, and lesson-learning from breaches. Specifically, the OPC noted inconsistent assessments of breach materiality, delays in notifying affected individuals, and a lack of concrete assistance such as credit monitoring. The OPC issued recommendations for consistent guidance on materiality, timely notification standards, offering mitigation measures, and robust incident assessment processes. All four institutions agreed to implement these recommendations.

Key Issues
  • Whether the institutions had adequate controls to prevent unauthorized disclosures of passports under s.8 of the Privacy Act
  • Whether the institutions had adequate measures to detect potential unauthorized disclosures of passports
  • Whether the institutions had adequate measures to remediate risks to individuals from unauthorized disclosures of passports
  • Whether the institutions consistently and appropriately assessed the "materiality" of passport-related breaches
  • Whether notifications to affected individuals regarding lost or stolen passports were timely
  • Whether concrete assistance, such as credit monitoring, was offered to individuals affected by lost or stolen passports
  • Whether incident assessment and investigation processes were robust enough to identify suspicious patterns and share lessons learned among relevant stakeholders